Falhas do tipo CWE-125

5.180 resultados

Leitura fora dos limites de memória

Ocorre quando o código tenta ler dados de uma posição de memória fora do intervalo alocado para um buffer ou array. O programa não valida o índice ou tamanho antes de acessar, causando leitura de dados inválidos, corrupção de informações ou revelação de dados sensíveis da memória adjacente.

Exemplo

Um processador de imagem PNG lê 4 bytes de um buffer de 2 bytes para validar uma assinatura, ou uma função copia uma string sem verificar se o índice fornecido pelo usuário extrapola o tamanho real do array. Em ambos os casos, dados fora do escopo pretendido são lidos.

Como mitigar

Sempre validar índices e comprimentos contra os limites reais do buffer antes de qualquer leitura. Usar funções seguras (ex: `strncpy` em vez de `strcpy`, bounds-checking em loops) e implementar testes com entradas extremas (size zero, índices negativos, valores muito grandes).

CVE-2026-56788MEDIUMRTKLIB 2.4.3 - Out-of-bounds Read via Negative Array Index in getcodepriEPSS 0.2%CVE-2026-61555MEDIUMOpenEXR: Empty multiView viewFromChannelName file crashEPSS 0.2%CVE-2026-23720HIGHA vulnerability has been identified in Simcenter Femap (All versions < V2512), Simcenter Nastran (All versions < V2512). The affected applicEPSS 0.2%CVE-2026-81334MEDIUMdarknet through 6.0 Out-of-Bounds Read and Write via Unchecked Layer Index in .cfg ParserEPSS 0.2%CVE-2021-37672MEDIUMHeap OOB in `SdcaOptimizerV2` in TensorFlowEPSS 0.2%CVE-2026-85698MEDIUMTurso through 0.8.0-pre.8 Out-of-Bounds Read Denial of ServiceEPSS 0.2%CVE-2026-16512LOWOut-of-bounds read in the Zephyr gPTP receive path when handling short Ethernet framesEPSS 0.2%CVE-2021-37685MEDIUMHeap OOB in TensorFlow LiteEPSS 0.2%CVE-2026-59985MEDIUMOpenEXR: Heap out-of-bounds read in OpenEXRCore RLE decoding on ILP32EPSS 0.2%CVE-2026-59983MEDIUMOpenEXR: Out-of-bounds read in DeepTiledInputFile sample-count table decode on ILP32EPSS 0.2%CVE-2026-17054MEDIUMOut-of-bounds read and permanent loss of Wi-Fi reception in the ESP-hosted SPI driver's frame reassemblyEPSS 0.2%CVE-2026-56391MEDIUMOut‑of‑bounds Read in GNU coreutilsEPSS 0.2%CVE-2022-42532MEDIUMIn Pixel firmware, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure witEPSS 0.2%CVE-2023-21510MEDIUMOut-of-bounds Read vulnerability while processing BC_TUI_CMD_UPDATE_SCREEN in bc_tui trustlet from Samsung Blockchain Keystore prior to versEPSS 0.2%CVE-2021-46768MEDIUMInsufficient input validation in SEV firmware may allow an attacker to perform out-of-bounds memory reads within the ASP boot loader, potentEPSS 0.2%CVE-2026-90994MEDIUMSssd: sssd: denial of service via malformed pam v1 requestsEPSS 0.2%CVE-2025-9447HIGHOut-Of-Bounds Read affecting the PAR file reading procedure in SOLIDWORKS eDrawings on Release SOLIDWORKS Desktop 2025EPSS 0.2%CVE-2022-42530MEDIUMIn Pixel firmware, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure witEPSS 0.2%CVE-2023-21507MEDIUMOut-of-bounds Read vulnerability while processing BC_TUI_CMD_SEND_RESOURCE_DATA_ARRAY command in bc_tui trustlet from Samsung Blockchain KeyEPSS 0.2%CVE-2023-21511MEDIUMOut-of-bounds Read vulnerability while processing CMD_COLDWALLET_BTC_SET_PRV_UTXO in bc_core trustlet from Samsung Blockchain Keystore priorEPSS 0.2%